View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
14947 | Bug reports | Security | public | 2019-05-28 16:55 | 2019-05-29 11:14 |
Reporter | tassoman | Assigned To | DenisChenu | ||
Priority | none | Severity | minor | ||
Status | closed | Resolution | duplicate | ||
Product Version | 3.16.x | ||||
Fixed in Version | 3.17.x | ||||
Summary | 14947: Question upload plugin, XSS during title, comment form filling | ||||
Description | While people is answering a «Question Upload» question type, they might be able to fill «Title» and «Comment» to its files. | ||||
Steps To Reproduce | Answer a survey having «Question upload» question type. | ||||
Additional Information | As mitigation, filtering is made after file get submitted to the server and survey managers can disable title and comment fields. | ||||
Tags | No tags attached. | ||||
Bug heat | 250 | ||||
Complete LimeSurvey version number (& build) | 3.16.1+190314 | ||||
I will donate to the project if issue is resolved | No | ||||
Browser | Firefox | ||||
Database type & version | MySql | ||||
Server OS (if known) | Centos7 | ||||
Webserver software & version (if known) | Apache | ||||
PHP Version | 7.2 | ||||
duplicate of | 14737 | closed | DenisChenu | XSS with file upload |
Date Modified | Username | Field | Change |
---|---|---|---|
2019-05-28 16:55 | tassoman | New Issue | |
2019-05-29 11:14 | DenisChenu | Relationship added | duplicate of 14737 |
2019-05-29 11:14 | DenisChenu | Assigned To | => DenisChenu |
2019-05-29 11:14 | DenisChenu | Status | new => closed |
2019-05-29 11:14 | DenisChenu | Resolution | open => duplicate |
2019-05-29 11:14 | DenisChenu | Fixed in Version | => 3.17.x |